Tor
by Torproject
Source repositories
CVEs (67)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2009-0936 | 0.00 | — | 0.02 | Mar 18, 2009 | Unspecified vulnerability in Tor before 0.2.0.34 allows attackers to cause a denial of service (infinite loop) via "corrupt votes." | |||
| CVE-2009-0654 | 0.00 | — | 0.02 | Feb 20, 2009 | Tor 0.2.0.28, and probably 0.2.0.34 and earlier, allows remote attackers, with control of an entry router and an exit router, to confirm that a sender and receiver are communicating via vectors involving (1) replaying, (2) modifying, (3) inserting, or (4) deleting a single cell,… | |||
| CVE-2009-0414 | 0.00 | — | 0.03 | Feb 3, 2009 | Unspecified vulnerability in Tor before 0.2.0.33 has unspecified impact and remote attack vectors that trigger heap corruption. | |||
| CVE-2008-5398 | 0.00 | — | 0.02 | Dec 9, 2008 | Tor before 0.2.0.32 does not properly process the ClientDNSRejectInternalAddresses configuration option in situations where an exit relay issues a policy-based refusal of a stream, which allows remote exit relays to have an unknown impact by mapping an internal IP address to the… | |||
| CVE-2008-5397 | 0.00 | — | 0.00 | Dec 9, 2008 | Tor before 0.2.0.32 does not properly process the (1) User and (2) Group configuration options, which might allow local users to gain privileges by leveraging unintended supplementary group memberships of the Tor process. | |||
| CVE-2007-4096 | 0.00 | — | 0.02 | Jul 30, 2007 | Buffer overflow in Tor before 0.1.2.15, when using BSD natd support, allows remote attackers to cause a denial of service via unspecified vectors. | |||
| CVE-2007-4099 | 0.00 | — | 0.02 | Jul 30, 2007 | Tor before 0.1.2.15 can select a guard node beyond the first listed never-before-connected-to guard node, which allows remote attackers with control of certain guard nodes to obtain sensitive information and possibly leverage further attacks. |
- CVE-2009-0936Mar 18, 2009risk 0.00cvss —epss 0.02
Unspecified vulnerability in Tor before 0.2.0.34 allows attackers to cause a denial of service (infinite loop) via "corrupt votes."
- CVE-2009-0654Feb 20, 2009risk 0.00cvss —epss 0.02
Tor 0.2.0.28, and probably 0.2.0.34 and earlier, allows remote attackers, with control of an entry router and an exit router, to confirm that a sender and receiver are communicating via vectors involving (1) replaying, (2) modifying, (3) inserting, or (4) deleting a single cell,…
- CVE-2009-0414Feb 3, 2009risk 0.00cvss —epss 0.03
Unspecified vulnerability in Tor before 0.2.0.33 has unspecified impact and remote attack vectors that trigger heap corruption.
- CVE-2008-5398Dec 9, 2008risk 0.00cvss —epss 0.02
Tor before 0.2.0.32 does not properly process the ClientDNSRejectInternalAddresses configuration option in situations where an exit relay issues a policy-based refusal of a stream, which allows remote exit relays to have an unknown impact by mapping an internal IP address to the…
- CVE-2008-5397Dec 9, 2008risk 0.00cvss —epss 0.00
Tor before 0.2.0.32 does not properly process the (1) User and (2) Group configuration options, which might allow local users to gain privileges by leveraging unintended supplementary group memberships of the Tor process.
- CVE-2007-4096Jul 30, 2007risk 0.00cvss —epss 0.02
Buffer overflow in Tor before 0.1.2.15, when using BSD natd support, allows remote attackers to cause a denial of service via unspecified vectors.
- CVE-2007-4099Jul 30, 2007risk 0.00cvss —epss 0.02
Tor before 0.1.2.15 can select a guard node beyond the first listed never-before-connected-to guard node, which allows remote attackers with control of certain guard nodes to obtain sensitive information and possibly leverage further attacks.
Page 4 of 4